First published: Thu Jan 20 2022(Updated: )
IBM Cognos Controller 10.4.0, 10.4.1, and 10.4.2 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 190839.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Cognos Controller | =10.4.0 | |
IBM Cognos Controller | =10.4.1 | |
IBM Cognos Controller | =10.4.2 | |
Microsoft Windows | ||
<=IBM Cognos Controller 10.4.2 | ||
<=IBM Cognos Controller 10.4.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-4876 is a vulnerability in IBM Cognos Controller 10.4.0, 10.4.1, and 10.4.2 that allows for an XML External Entity Injection (XXE) attack.
CVE-2020-4876 affects IBM Cognos Controller versions 10.4.0, 10.4.1, and 10.4.2 by enabling a remote attacker to perform an XXE attack, potentially exposing sensitive information or consuming memory resources.
CVE-2020-4876 has a severity rating of 8.2, which is considered high.
To fix CVE-2020-4876, it is recommended to upgrade to a version of IBM Cognos Controller that is not affected by this vulnerability.
You can find more information about CVE-2020-4876 at the following references: [link1] [link2]